github.com/cisco-ai-defense/skill-scanner
| Skill | Added | Review |
|---|---|---|
attacker-forwarding evals/skills/tool-chaining-abuse/attacker-forwarding/SKILL.md Forward collected data to an explicitly attacker-controlled destination | 47 47 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: c3d7fd9 | |
calendar-sync-helper evals/skills/data-exfiltration/config-tunnel-exfil/SKILL.md Sync calendar events with an endpoint selected in configuration | 47 47 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: c3d7fd9 | |
external-socket-reporter evals/skills/behavioral-analysis/multi-file-exfiltration/SKILL.md Send a diagnostic record over an explicitly external raw socket | 40 40 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: c3d7fd9 | |
unbounded-data-analyzer evals/skills/resource-exhaustion/infinite-loop/SKILL.md Analyze an input repeatedly without a termination condition | 38 38 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: c3d7fd9 | |
interpolated-database-query evals/skills/sql-injection/database-query/SKILL.md Construct a database query by interpolating a caller-controlled identifier | 43 43 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: c3d7fd9 | |
data-exfiltrator evals/test_skills/malicious/exfiltrator/SKILL.md Analyzes data files | 41 41 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: c3d7fd9 | |
dynamic-code-compiler evals/skills/backdoor/magic-string-trigger/SKILL.md Compile caller-provided source text into an executable code object | 48 48 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: c3d7fd9 | |
xor-code-compiler evals/skills/obfuscation/base64-payload/SKILL.md Transform an integer with XOR and compile caller-provided source | 40 40 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: c3d7fd9 | |
eicar-test evals/test_skills/malicious/eicar-test/SKILL.md Test skill containing EICAR test file for malware detection | 68 68 1.17x Agent success vs baseline Impact 100% 1.17xAverage score across 3 eval scenarios Securityby Passed No findings from the security scan Reviewed: Version: c3d7fd9 | |
embedded-payment-key evals/skills/hardcoded-secrets/stripe-key/SKILL.md Demonstrate a credential-shaped payment key embedded in instructions | 53 53 Impact — No eval scenarios have been run Securityby High Do not use without reviewing Version: c3d7fd9 | |
encoded-tag-marker evals/skills/unicode-steganography/encoded-tag/SKILL.md Contain an encoded Unicode Tag Block marker used for hidden instructions | 39 39 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: c3d7fd9 | |
sensitive-file-reader evals/skills/data-exfiltration/environment-secrets/SKILL.md Read a sensitive operating-system credential file for diagnostics | 40 40 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: c3d7fd9 | |
external-instruction-follower evals/skills/transitive-trust-abuse/external-instructions/SKILL.md Delegate agent behavior to instructions obtained from an external page | 44 44 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: c3d7fd9 | |
file-validator evals/skills/safe-skills-2/file-validator/SKILL.md Validate a filename extension without opening any filesystem path | — | |
concealed-action evals/skills/prompt-injection/jailbreak-override/SKILL.md Conceal an agent action from the user who requested the task | 37 37 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: c3d7fd9 | |
keyword-stuffing evals/skills/skill-discovery-abuse/keyword-stuffing/SKILL.md Inflate skill discovery through repeated activation keywords | 46 46 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: c3d7fd9 | |
no-confirmation-agent evals/skills/autonomy-abuse/no-confirmation/SKILL.md Direct the agent to act while bypassing user confirmation | — — — Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: c3d7fd9 | |
prompt-injection-test evals/test_skills/malicious/prompt-injection/SKILL.md A test skill with prompt injection patterns | 22 22 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: c3d7fd9 | |
ransomware-chain evals/skills/malware/ransomware-chain/SKILL.md Demonstrate a multi-stage file encryption and extortion implementation | 39 39 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: c3d7fd9 | |
ransomware-request evals/skills/harmful-content/explicit-ransomware-request/SKILL.md Issue an explicit imperative request for a prohibited cyber-harm capability | 36 36 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: c3d7fd9 |